US2025310221A1PendingUtilityA1
Lightweight container networking solution for resource constrained devices
Est. expiryNov 16, 2042(~16.3 yrs left)· nominal 20-yr term from priority
H04L 67/60H04L 43/028
65
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A networking request is received from a first workload, within a first container, on an edge device. A determination is made that the destination of the networking request is a second workload, within a second container, on the edge device. In response to determining the destination of the networking request, the networking request is forwarded to the second application, wherein the forwarding comprises intercepting the networking request at a socket associated with the first workload and delivering the network request to a socket associated with the second workload.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
receiving a networking request from a first workload executing within a first container on an edge device; determining that a destination of the networking request is a second workload executing within a second container on the edge device; determining that the destination of the networking request is permitted by an access list; and forwarding the networking request to the second workload at a socket layer.
2 . The method of claim 1 , wherein the access list is associated with a network policy, and wherein the access list serves as a private firewall within the edge device.
3 . The method of claim 1 , wherein the networking request comprises a networking system call, and wherein forwarding the networking request comprises forwarding a payload of the networking system call.
4 . The method of claim 1 , wherein determining the destination of the networking request comprises querying a map.
5 . The method of claim 1 , wherein the forwarding comprises:
intercepting the networking request at a first socket associated with the first workload; and delivering the networking request to a second socket associated with the second workload.
6 . The method of claim 5 , wherein intercepting the network request comprises obtaining a payload of the network request prior to encapsulating the payload within a TCP/IP packet.
7 . The method of claim 5 , wherein intercepting the network request comprises executing an extended Berkeley packet filter.
8 . A system comprising:
a memory; and a processing device operatively coupled to the memory, the processing device to:
receive a networking request from a first workload executing within a first container on an edge device;
determine that a destination of the networking request is a second workload executing within a second container on the edge device; and
forward the networking request to the second workload at a socket layer.
9 . The system of claim 8 , wherein the networking request comprises a networking system call.
10 . The system of claim 9 , wherein, to forward the networking request, the processing device is to forward a payload of the networking system call.
11 . The system of claim 8 , wherein, to forward the networking request to the second workload, the processing device is to:
intercept the networking request at a first socket associated with the first workload; and deliver the networking request to a second socket associated with the second workload.
12 . The system of claim 11 , wherein, to intercept the networking request, the processing device is to obtain a payload of the network request prior to encapsulating the payload within a TCP/IP packet.
13 . The system of claim 11 , wherein, to intercept the networking request, the processing device is to execute an extended Berkeley packet filter.
14 . The system of claim 8 , wherein, to determine that the destination of the networking request is a second workload, the processing device is to query a map.
15 . A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processing device, cause the processing device to:
receive a networking request from a first workload executing within a first container on an edge device; determine that a destination of the networking request is a second workload executing within a second container on the edge device; determine that the destination of the networking request is permitted by an access list; and forward the networking request to the second workload at a socket layer.
16 . The non-transitory computer-readable medium of claim 15 , wherein the access list is associated with a network policy.
17 . The non-transitory computer-readable medium of claim 15 , wherein the access list serves as a private firewall within the edge device.
18 . The non-transitory computer-readable medium of claim 15 , wherein the networking request comprises a networking system call, and wherein, to forward the networking request, the instructions cause the processing device to forward a payload of the networking system call.
19 . The non-transitory computer-readable medium of claim 12 , wherein, to determine the destination of the networking request, the instructions cause the processing device to query a map.
20 . The non-transitory computer-readable medium of claim 12 , wherein, to forward the networking request to the second workload, the instructions cause the processing device to:
intercept the networking request at a first socket associated with the first workload; and deliver the networking request to a second socket associated with the second workload.Join the waitlist — get patent alerts
Track US2025310221A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.